< ciso
brief />
Vendor and Hyperscaler Watch Banner

All news in category “Vendor and Hyperscaler Watch”

5915 articles · page 18 of 296

Architecting a Secure Landing Zone in EUSC

🔒 This post explains how to design a secure, scalable landing zone for the AWS European Sovereign Cloud (aws-eusc), a partitioned AWS environment operated within the EU. It covers account structure and governance, identity as IaC, centralized logging to a SIEM, data protection, perimeter and network design, CI/CD and artifact distribution, and incident response. The guidance maps to the AWS Security Reference Architecture and the AWS Well-Architected Framework, and highlights which behaviors are partition boundaries versus configurable choices.
read more →

Client-side security uncovers four malicious campaigns

🔍 Cloudflare describes how its Page Shield Client-Side Security ML uncovered four distinct malicious JavaScript operations running on storefronts. The post explains that automated GNN analysis (with LLM second opinions) detected eight payloads in live traffic that other scanners missed, and details how the scripts siphoned affiliate revenue, hijacked clicks, suppressed analytics, and conditionally loaded remote code. It highlights delivery via tag managers, typosquatted hosts, time- and browser-gated execution, and the need for sustained browser visibility to catch cloaked threats.
read more →

AWS Client VPN Adds macOS 27 Golden Gate Support

🖥️ AWS Client VPN now supports macOS 27 Golden Gate with client versions 6.0 and later. The AWS-supplied desktop VPN client can be run on the latest macOS releases and remains available free of charge. Client VPN is a managed service that securely connects remote users to AWS and on-premises networks and supports macOS, Windows (x64 and Arm64) and Ubuntu Linux clients.
read more →

AWS launches simplified Builder experience

🔧 Builders can now sign up for a simplified experience that speeds turning ideas into running code on AWS. The new flow reduces setup effort by auto-configuring an initial project with sensible defaults and supports sign-in via Google, GitHub, Apple, or Amazon credentials. New customers may receive up to $200 in free credits and no credit card is required for most signups. Projects include automated IAM role management, team invites, per-project spend limits, and easy upgrades to advanced features without downtime.
read more →

Amazon WorkSpaces adds NVIDIA Blackwell G7 bundles

🚀 Amazon WorkSpaces Personal and Core now offer Graphics G7 bundles powered by NVIDIA RTX PRO 4500 Blackwell Server Edition GPUs and Intel Xeon 6 processors. These bundles deliver up to 2.1x better graphics performance versus Graphics G6 and come in four sizes from 8 vCPUs/32 GB/1 GPU to 48 vCPUs/192 GB/2 GPUs. Graphics G7 supports demanding professional workloads, Windows licensing options, AlwaysOn and AutoStop modes, and is initially available in three US Regions with broader rollout planned.
read more →

Amazon Connect imports evaluation form PDFs with AI

🤖 Amazon Connect Customer now supports importing evaluation form PDFs from third-party quality management applications and uses AI to recreate them within Connect. The service extracts sections, questions, answer options, and scoring into a draft form after you choose percentage or points-based scoring. You can provide natural language instructions to refine the import, reducing manual edits before activation. This feature is available in multiple AWS Regions including N. Virginia, Oregon, Singapore, Sydney, Tokyo, Frankfurt, and Canada (Central).
read more →

Amazon Connect Customer adds tag-based access control

🔐 Amazon Connect Customer now supports tag-based access control for custom metrics, enabling administrators to govern who can view, create, or modify each metric. This lets teams tag metrics and assign permissions so they retain full control over their own metrics, have view-only access to other teams’ metrics, or are prevented from seeing restricted metrics. Search results respect these access controls. The feature is available in all Regions where Amazon Connect Customer is offered.
read more →

MediaTailor adds new monetization function hooks

🔔 AWS Elemental MediaTailor now supports two additional monetization function lifecycle hooks: post ADS response and pre manifest insertion. These hooks let customers run custom logic after ADS responses are parsed and just before ad pods are returned to viewers, enabling secondary ad sourcing, policy-based ad removal, house ads, and final checks including personalized slates. Pre-built recipes are available and both hooks are fail-open to avoid playback disruption.
read more →

Amazon ECS adds S3 Files support for EC2 tasks

📁 Amazon Elastic Container Service (Amazon ECS) now supports Amazon S3 Files for tasks using the Amazon EC2 launch type, allowing containerized applications to access S3 data as a shared file system. This extension enables file-based applications, AI agents, and data processing workloads to use standard file system semantics without code changes or data duplication. S3 Files was already available for ECS on AWS Fargate and ECS Managed Instances and now provides consistent access across all three ECS launch types.
read more →

Microsoft named Leader in 2026 Distributed Hybrid MQ

🟦 Microsoft was named a Leader in the 2026 Gartner® Magic Quadrant™ for Distributed Hybrid Infrastructure, ranking highest for Ability to Execute. The post highlights how Azure Local and Azure Arc deliver a unified approach to manage infrastructure across datacenters, edge, multi-cloud, and sovereign environments. It explains options for sovereignty, disconnected operations, and AI inference at the edge with Foundry Local, emphasizing consistent management and operational simplicity.
read more →

Amazon Keyspaces expands availability to 11 Regions

🚀 Amazon Keyspaces (for Apache Cassandra) is now generally available in 11 additional AWS Regions, enabling customers to run Cassandra-compatible applications with lower latency and meet regional data residency requirements. Amazon Keyspaces is a managed, serverless, and highly available Cassandra-compatible database service that scales for high throughput and storage demands. Customers pay only for resources used and can serve thousands of requests per second with virtually unlimited capacity. New Region availability details are provided in AWS region capability listings.
read more →

SeaVerse selects GKE Agent Sandbox for isolation

🎮 SeaVerse, a SeaArt gaming startup, built a platform for playable AI experiences and needed infrastructure that could run dynamic, multi-tenant sandboxes with low latency, strong isolation, and better observability. By adopting Google Kubernetes Engine (GKE) and GKE Agent Sandbox, SeaVerse achieved kernel-level isolation with microVMs and gVisor options, improved runtime visibility, and scaled sandbox allocations rapidly. The change reduced infrastructure costs by up to 60% while preserving a fast creator experience.
read more →

Google CISO Views on Monitoring and Defending AI

🔒 Sandra Joyce outlines Google’s frontline view of AI-driven threats and the firm’s defensive strategy. She explains three structural shifts—AI reshaping software development, expanding attack surfaces, and enhancing threat capabilities—and describes how Google integrates multi-model telemetry, code-to-cloud context, and automated remediation to protect organizations. The piece emphasizes moving from siloed tools to unified, machine-speed defenses.
read more →

Amazon Connect Customer adds APIs for custom metrics

📈 Amazon Connect Customer now supports programmatic creation, management, and search of custom metrics through seven new API operations. These include CreateMetric, DeleteMetric, DescribeMetric, ListMetrics, SearchMetrics, UpdateMetricContent, and UpdateMetricMetadata. Changes are logged in AWS CloudTrail and the feature is available in all Regions where Amazon Connect Customer is offered.
read more →

Google Cloud unveils M4N VMs for I/O‑heavy workloads

🚀 Google Cloud has launched the M4N machine series in Compute Engine, designed for I/O-intensive, high-memory workloads and now generally available. Built on 5th Gen Intel® Xeon® Scalable processors and Google’s Titanium offload architecture, M4N delivers up to 6TB RAM, 25 GiB/s aggregate host storage throughput, and up to 1 million IOPS with Hyperdisk Extreme. The family targets mission-critical databases, generative AI data layers, healthcare ERP, and real-time analytics while promising >20% TCO reduction for Oracle workloads.
read more →

How Orange Mobilized Teams for FinOps Success

🔍 At Orange, engineers participate in collaborative FinOps Clean Days and gamified hackathons to drive cost optimization and learning, producing an internal Net Promoter Score above 70 for its 100+ person FinOps community. The company treats FinOps as a business change problem, emphasizing shared responsibility, a Community of Practice, and protected time for optimization. Orange pairs these cultural practices with AI agents to scale engagement: read-only agents for insights and suggested fixes, then execution-capable agents when trust and governance are established. The approach follows McKinsey’s change-building blocks—conviction, formal mechanisms, role modeling, and skills—so cultural foundation comes first, then agent-driven automation to reduce friction and extend FinOps practices across thousands of engineers.
read more →

NIST and CISA guidance leaves AI agent authorization gap

🔐 NIST’s new report, Protecting Tokens and Assertions from Forgery, Theft, and Misuse (IR 8587), gives guidance for securing digitally signed tokens used in SSO and API access, but leaves agent authority questions unresolved. The guidance recommends continuous monitoring, lifecycle controls, and token hardening, while noting AI agents introduce additional IAM challenges. Organizations should inventory agents, use short-lived credentials, and treat agents as low-trust non-human identities that require constrained, task-limited access.
read more →

Amazon Connect Talent: AI hiring at scale

🤖 Amazon Connect Talent is now generally available as an AI-powered hiring solution for talent acquisition leaders. Informed by Amazon's hiring science, it uses AI agents to conduct structured voice interviews, administer evidence-based competency assessments, and consistently score candidates. The service supports 24/7 interviews from any device, provides transcripts and detailed evaluations, and includes a brand-customizable candidate portal and admin tools for scaling hiring operations.
read more →

Microsoft outlines workaround for missing Outlook Copilot

🛈 Microsoft confirmed a known issue that causes the Copilot and Copilot Chat buttons to disappear in Classic Outlook for Windows for customers with Copilot Chat (Basic) or paid M365 Copilot licenses. The problem appears after upgrading Classic Outlook to build 20026.20182 or later, and Outlook cannot locate a required MAPI property, preventing Copilot settings from persisting. Microsoft advised enabling Show Apps in Outlook as a temporary workaround, creating a new Outlook profile, or using the new Outlook client or OWA while it investigates a permanent fix.
read more →

When Threat Intelligence Requires Active Validation

🔎 Intelligence alerts are valuable early signals, but the true problem is the queue of unvalidated items that allows risk to accumulate. Organizations often lack the time and offensive expertise to test each indicator, turning volume into backlog. Threat-led penetration testing (TLPT) reframes testing to validate current intelligence—confirming whether a leaked credential or disclosed vulnerability is exploitable in a specific environment. Practical integrations, such as Pentera with Recorded Future, automate validation runs to prioritize proof over probability.
read more →